Welcome to the #dominoforever Product Ideas Forum! The place where you can submit product ideas and enhancement request. We encourage you to participate by voting on, commenting on, and creating new ideas. All new ideas will be evaluated by HCL Product Management & Engineering teams, and the next steps will be communicated. While not all submitted ideas will be executed upon, community feedback will play a key role in influencing which ideas are and when they will be implemented.
For more information and upcoming events around #dominoforever, please visit our Destination Domino Page
We could add this to the backlog, but in all honesty we will probably never get to it.
Marking as "No Plans to Implement".
I assume that you are implementing SAML and you want to differentiate between the external, which must authenticate via MFA/TOTP, and internal users, which should authenticate via WIA or a similar mechanism.
For me, the better alternative is to use Split-Brain DNS. Use your hosted DNS service to redirect external users to HCL SafeLinx, where MFA/TOTP is used for authentication. Via your "internal" DNS service you can redirect the clients to the SP directly (HCL Domino, HCL Traveler, etc....), which in terms redirects the clients to your IdP and authenticates them via the desired protocol (WIA, username/PW, certificate based authentication, etc....).
Some SAML IdPs can differentiate between external and internal clients, thus providing different authentication mechanisms. Depending on your use-case, this is a good option.
As in other comment, you could also try creating two http-services, using different authentication mechanisms, and binding them to different NICs.
If you have any further questions, post a question, with additional information, in the HCL community forums or create a Ticket:
https://support.hcltechsw.com/csm
HTH
Have you tried binding the service to the two NICs that you would have? One internal and one external.